CERT-MU Vulnerability Note VN-2009-26
Adobe Reader and Acrobat Remote Code Execution Vulnerability
Original Issue Date: October 14, 2009
Severity Rating: High
Affected Softwares
- Adobe Reader 9.1.3 and earlier versions
- Adobe Acrobat 9.1.3 and earlier versions
Overview
A vulnerability has been reported in Adobe Reader and Acrobat, which could allow a remote attacker to execute an arbitrary code or causes denial of service condition.
Description
This vulnerability is caused due to an unspecified error in parsing PDF file in Adobe Reader and Acrobat. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted PDF file resulting in arbitrary code execution in the context of the user running the affected application or cause denial of service (DoS) condition.
Workarounds
- Disable JavaScript until vendor fixes available.
- Do not open PDF documents received from untrusted sources.
- Enable Data Execution Prevention (DEP) on Windows Vista.
Vendor Information
Adobe
http://www.adobe.com/support/security/bulletins/apsb09-15.html
CVE Name
CVE-2009-3459
References
Adobe
http://www.adobe.com/support/security/bulletins/apsb09-15.html
http://blogs.adobe.com/psirt
SecurityFocus
http://www.securityfocus.com/bid/36600/
SecurityTracker
http://www.securitytracker.com/alerts/2009/Oct/1022998.html
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
|